5 unchanged sentences
The Company’s commitment to cybersecurity is integral to its business strategy, operational integrity, and brand reputation.
−Removed: Leading the Company’s cybersecurity risk management and strategy at the management level is our Senior Director of Information Security, who reports directly to the Vice President of Information Technology.
−Removed: The Senior Director of Information Security has been with the Company for over 18 years, serving in various capacities with deep understanding of the underlying architecture, technologies, and systems utilized by the Company.
−Removed: The Senior Director of Information Security and his team are responsible for designing and implementing the Company’s strategies, policies, and processes to assess, identify, and manage risk related to cybersecurity threats, along with threats associated with our use of third-party service providers.
−Removed: A combination of industry-leading tools, relationships with external experts, in-house expertise, and in-house technologies are integral to the Company’s strategy for managing cybersecurity threats.
+Added: Leading the Company’s cybersecurity risk management and strategy at the management level is our Vice President of Information Security, who reports directly to the Vice President of Information Technology.
+Added: The Vice President of Information Security has been with the Company for over 19 years, serving in various capacities with deep understanding of the underlying architecture, technologies, and systems utilized by the Company.
+Added: The Vice President of Information Security and his team are responsible for designing and implementing the Company’s strategies, policies, and processes to assess, identify, and manage risk related to cybersecurity threats, along with threats associated with our use of third-party service providers.
+Added: A combination of widely accepted tools, relationships with external experts, in-house expertise, and in-house technologies are integral to the Company’s strategy for managing cybersecurity threats.
The Company executes ongoing assessment and testing of processes and practices through regular teammate training, phishing exercises, network and endpoint monitoring, penetration testing, vulnerability scanning, and attack simulations.
−Removed: The Company’s incident response plan is based on recognized industry best practice security standards and control frameworks, such as the National Institute of Standards and Technology Cybersecurity (“NIST”) Framework.
+Added: The Company’s incident response plan is based on recognized industry security standards and control frameworks, such as the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework.
Third parties are also engaged to perform assessments and validate the Company’s cybersecurity measures, including information security maturity assessments and independent reviews of the operating effectiveness of the information security control environment.
1 unchanged sentence
While the Board of Directors is ultimately accountable for risk management, the Audit Committee oversees management’s processes for identifying, implementing, and mitigating cybersecurity threats.
−Removed: On at least a quarterly basis, the Senior Director of Information Security provides the Audit Committee with updates regarding the Company’s ongoing cybersecurity program.
+Added: On at least a quarterly basis, the Vice President of Information Security provides the Audit Committee with updates regarding the Company’s ongoing cybersecurity program.
These updates regularly cover the latest in the Company’s evolving approach to managing cybersecurity risks, reviewing key metrics on the effectiveness of the program, and discussing recent developments, key strategic initiatives, the current threat environment, and outcomes from specific evaluations and tests.
+Added: Additionally, to ensure appropriate knowledge and oversight of cybersecurity risks, the Audit Committee Chair holds a CERT Certificate in Cybsersecurity Oversight from the CERT Division of the Software Engineering Institute at Carnegie Mellon University, which he earned in January 2024.
Cybersecurity Monitoring and Mitigation
−Removed: In addition to the ongoing cybersecurity program management carried out by the Senior Director of Information Security, the Company also has the Buckle Incident Response Team (“BIRT”), a cross-functional group with relevant expertise and authority to support all aspects of the incident response, recovery, and reporting of a security incident.
+Added: In addition to the ongoing cybersecurity program management carried out by the Vice President of Information Security, the Company also has the Buckle Incident Response Team (“BIRT”), a cross-functional group with relevant expertise and authority to support all aspects of the incident response, recovery, and reporting of a security incident.
BIRT uses a well-defined incident response plan that outlines processes to prepare for and detect cybersecurity threats, analyze the severity, materiality, and impacts, determine who should be notified and involved in the Company’s response, and define actions necessary to contain and recover in the event of an incident.
5 unchanged sentences
Although the Company has combatted cybersecurity threats in the normal course of business, these threats have not materially affected its operations, business strategy, results of operations, or financial condition.
−Removed: While the Company strives to implement best-in-class cybersecurity measures, it recognizes that the threat landscape is continually evolving.
+Added: While the Company strives to implement highly effective cybersecurity measures, it recognizes that the threat landscape is continually evolving.
Future attacks, if not successfully prevented or mitigated, could materially affect the Company, including its operations, business strategy, results of operations, or financial condition.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.